Get a clear plan, founder-led support, and an AI agent that helps prepare policies and collect evidence. Keep your team focused on building while you work toward your audit.
30 minutes with the founder · Written next steps · No purchase required
Founder-led onboardingShared Slack channelYour choice of auditor
SOC 2HIPAAISO 27001ISO 42001GDPR
Animated product demo: Screenata scans your systems, assesses SOC 2 readiness, remediates gaps, collects your review and sign-off, and delivers a signed audit package to your auditor.
AcmeIntegrationsSOC 2 Type II— Ask Vera
Audit cycle · Jan 1 – Jun 30
Scan
Assess
Remediate
Review
Report
Integrations
Connected read-only. Vera scans on a schedule.
Connected 6Available 54 Add
Connected
6
of 60 available
Checks run
0
mapped to controls
Last scan
RunningJust now
Read-only · no agents
IntegrationCategoryStatusChecks
AWSCloudScanningConnected312
OktaIdentityScanningConnected75
GitHubCodeScanningConnected133
Google WorkspaceProductivityScanningConnected58
DatadogMonitoringScanningConnected44
SlackCommunicationScanningConnected28
Vera650 checks across 6 systems
A person to turn to
Founder-led support. From your first connection to audit preparation.
Work directly with Screenata’s founder to connect your systems, review generated policies, and build your first evidence plan. Founder-led onboarding is included for our current cohort, with scope agreed before you sign.
A shared Slack channel with the founder.
Your team gets a shared Slack channel with Screenata’s founder for setup questions, product help, and blockers. We agree support hours and check-in times during onboarding.
What we work on together
Help connecting your cloud, code repositories, and identity provider
Company profile, audit scope, and a system description scope draft
A walkthrough of generated policies for your review
An evidence plan with the next actions and owners
A readiness check before your auditor starts
01
Agree your scope
Start with the customer request, your systems, and your target date. Agree what the platform, your team, and any partner will cover.
02
Prepare and review
Connect your systems. Vera drafts policies and gathers evidence; we help you work through setup and the next actions. Your team reviews and approves.
03
Prepare for auditor review
Check readiness and organize the evidence package. Your independent auditor reviews the evidence and issues the report.
What your team, Screenata, and your auditor each own
Your team provides access and accurate information, reviews and approves policies, operates its controls, and fixes infrastructure gaps. Your independent auditor decides whether the evidence is sufficient and issues the report.
Infrastructure remediation, advisory beyond the agreed program, and hands-on audit fieldwork support are scoped separately with a delivery partner when needed. The independent audit fee is separate.
Vera writes the policies, collects the evidence, works through the gaps with your team, and assembles a signed audit package. You approve; your auditor issues the report.
Your compliance program
Every module included.
Scope agreed before signing
One program, every module.
Policies, evidence, monitoring, and audit preparation in one program. We work through your scope and support needs with you, then put the proposal in writing.
Every artifact is mapped to a control, dated, and signed, so any auditor can verify it independently. When an enterprise buyer's security team reads it line by line, the proof holds up.
“I really like… the focus on reducing manual work instead of just giving users another compliance dashboard to manage. The AI agent approach… feels more like having an assistant working with you instead of just showing you tasks.”
GRC consultantUsing Screenata with clients
01 · Policies
Scan first. Then write what you can prove.
Vera assembles context from GitHub, AWS or GCP, your IdP, and existing evidence before a single policy is written. The overpromise checker flags hard commitments unsupported by what she found, before your auditor does.
Policies grounded in real IAM policies, branch protection, and MFA settings
Overpromise detection, the #1 audit failure mode, caught at draft time
All 8 SOC 2 foundational deliverables, right-sized for startup teams
Acme Corp enforces multi-factor authentication through Okta for all administrative access to production systems. verified
Production access is reviewed quarterly by the security team to remove stale entitlements. overpromise
Vera flagged this claim
No quarterly access review evidence found in the last 12 months across Okta and GitHub. Soften to "periodic reviews as needed", or commit to quarterly and let me schedule them.
Soften languageSchedule quarterly review
02 · Evidence
Automate evidence collection beyond APIs.
API integrations are table stakes and cover about 30–40% of a SOC 2. The rest lives in screens and walkthroughs that other platforms hand back to you as a to-do list. Screenata captures those too, and evidence collected once counts toward every framework it satisfies.
01
API Automation
Cloud, code, and identity providers scanned on a schedule. Every check maps to a control and is signed on arrival.
S3 default encryption on all bucketssigned 6:00 AM
Branch protection on mainsigned 6:00 AM
CloudTrail retention 365 dayssigned 6:00 AM
Alerting on production errorssigned 6:00 AM
Controls satisfied
CC6.1Passing
CC6.7Passing
CC8.1Passing
CC7.2Passing
CC1.4Passing
650+ checks · 60+ providers · on a schedule
02
Screenshot Automation
Settings pages and admin consoles with no API, the evidence teams still screenshot by hand. Click the extension, or let a procedure trigger it on schedule. Captured, redacted, quality-checked, signed, filed.
Your team shouldn't have to sign in to one more platform to finish a request. Files dropped in Slack or emailed to your workspace address are filed as evidence and matched to the right test. Nobody has to open the dashboard.
Email your workspace address: attachments are filed as evidence, and Vera replies
Owners get a reminder before work is due and an alert when it's late
Daily freshness checks: fresh, stale at 90 days, expired at 120
Drafted remediation ticket, needs your approval to apply.
Reply to #compliance
04 · Proof
One sentence. One claim. One test. One signed artifact.
Screenata links each policy sentence to the control it satisfies, the test that checks it, and the signed evidence that proves it. Your team can see why a requirement exists and exactly what proves it. Your auditor can verify the artifact outside Screenata.
Trace any policy, claim, control, or test through to its evidence
Each test says what to provide and how your auditor will judge it
A free 30-minute readiness review with Screenata’s founder, based on your customer requirement, current setup, and target date. Get a written summary of scope, priority gaps, and next steps. No purchase or system access required.
Clear scope. Named responsibilities. A proposal in writing.
Frameworks, entities, infrastructure, and the deadline you’re working toward.
Our support
Founder-led onboarding, a shared Slack channel, and a practical evidence plan.
Your proposal
Platform, onboarding, responsibilities, and renewal terms agreed before signing.
Your auditor
Choose and contract with an independent audit firm directly.
FAQ
Know what happens before you start.
The free review, human support, your responsibilities, and the work Vera handles.
What do I get in the free readiness review?
A free 30-minute readiness review with Screenata’s founder, based on your customer requirement, current setup, and target date. Get a written summary of scope, priority gaps, and next steps. No purchase or system access required. This is an initial review based on what you share, not an audit or a complete verification of your controls. If Screenata fits, we can also provide a scoped proposal.
Who helps us when we get stuck?
Your team gets a shared Slack channel with Screenata’s founder for setup questions, product help, and blockers. We agree support hours and check-in times during onboarding.
What will our team still need to do?
Your team connects systems, provides accurate information, reviews and approves policies, operates controls, and fixes infrastructure gaps. Screenata helps prepare policies, collect evidence, and organize the next actions. If you need hands-on implementation or specialist advice, we can discuss a separately scoped delivery partner engagement.
How long will our SOC 2 take?
We review your scope, existing controls, evidence gaps, and team availability before agreeing milestones. A SOC 2 Type II also requires an observation period agreed with your auditor. Your independent auditor determines whether the evidence is sufficient and issues the report; the free readiness review does not guarantee an audit outcome or completion date.
What makes Screenata different from Vanta or Drata?
Evaluate the work each product handles for your actual setup. Screenata combines infrastructure-grounded policies, evidence collection through integrations and guided procedures, and founder-led onboarding. Ask us to demonstrate one of your evidence tasks and clarify what your team still needs to do.
How are policies generated?
Screenata scans first, then writes. We pull context from GitHub, AWS or GCP, your IdP, existing evidence, and your company profile, then generate policies grounded in what we found. The overpromise checker flags hard commitments (like 'quarterly access reviews') we cannot verify in evidence, before you ever ship them to an auditor.
How do you collect evidence that integrations can't reach?
Three channels, not one. API scans cover about 30–40% of a SOC 2 across cloud, code, and identity providers. The browser extension captures screenshots of settings pages and workflows, redacts sensitive fields, runs a vision quality check, signs the capture, and re-captures it on a schedule. Guided procedures walk a teammate through steps like a backup restore test and record results and attachments as they work. Your team reviews the output and supplies context where a task requires human judgment.
How is our price determined?
We review your frameworks, entities, infrastructure, and support needs, then put the scope, price, and responsibilities in writing. The free readiness review has no purchase requirement. You choose and pay your independent auditor separately.
No. Every test explains what to provide, which evidence items are required, and how your auditor will judge it, and you can ask Vera about any requirement in plain language. The lineage view traces a policy, claim, control, or test through to the evidence that proves it, so you can see why something is required. When a check fails, it comes with the recommended fix and the steps to apply it, and the finding closes on its own once the nightly re-check passes.
Start with a free readiness review
Bring the customer request. Leave with next steps.
A free 30-minute readiness review with Screenata’s founder, based on your customer requirement, current setup, and target date. Get a written summary of scope, priority gaps, and next steps. No purchase or system access required.